Field Notes

From the InfoSec Professional Desk

Practical writing on security operations, what to log, what to detect, and how defenders actually win.

All articles

Latest writing

Detection Engineering2 min read

PowerShell Logging for Blue Teamers

Module logging, script block logging and transcription, the three PowerShell logging layers every blue team should enable, and what each one actually catches.

Detection Engineering2 min read

Enhancing Threat Detection with Microsoft Sysmon

Why Sysmon remains the highest-value free telemetry on Windows, the events that matter, configuration philosophy, and detections to build first.

Medium archive

On Medium

Follow on Medium →

Everything I've published on Medium, each preview links to the full article at shreenkhalabhattarai.medium.com.